4 months ago
827cd21Memory entries and the hot cache are injected verbatim into future sessions' system prompts, and MCP tool descriptions (often from a remote/workspace server) are handed to the model as tool context. None had a size bound, so a model could persist an arbitrarily large payload that overflows the next session's context window, or a hostile MCP server could flood the toolset. - memory tool: cap content at 50k chars; MemoryStore.renderPromptSection now truncates the hot cache at 16k chars defensively (covers DBs written out-of-band or by older builds). - manageMemory: cap name/description/body (200/500/50k). - MCP discovery: cap tool descriptions at 4k chars. Adds memory cap + render-truncation regression tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parentd9f0be7